Self-hosted HTTP tunnels via SSH and Nginx

Original: Self-hosted HTTP tunnels with SSH and Nginx

Why This Matters

Shows engineers a no-dependency alternative to commercial tunnel services using standard infrastructure.

Engineer Vincent Bernat demonstrates building a self-hosted HTTP tunnel using only OpenSSH and Nginx, enabling localhost services to be shared publicly via wildcard subdomains, secure links, and Let's Encrypt certificates.

Bernat's setup solves a common developer problem: sharing a local web service (e.g., localhost:8080) with an external reviewer without relying on commercial tools like ngrok or Cloudflare Quick Tunnels. The approach uses SSH's built-in remote port forwarding (`ssh -R 0:localhost:8080 server`) to allocate a random port on the remote host. Nginx then proxies traffic from a matching wildcard subdomain (e.g., p41535.ssh.luffy.cx) to that port using a regex-based `server_name` directive. DNS is handled with a wildcard CNAME, and wildcard TLS certificates come from Let's Encrypt via DNS-01 ACME challenges delegated to Route 53. On the security side, Bernat acknowledges that a raw port number offers only about 14.8 bits of entropy — weak enough to warrant extra protection. He layers on Nginx's `ngx_http_secure_link_module`, embedding an MD5 hash and expiration timestamp in the URL as HTTP Basic Auth credentials (e.g., `hash--expiry@p41535.ssh.luffy.cx`). This prevents port-reuse attacks and makes enumeration harder. The full flow is wrapped in a single shell command with a helper script. No custom server software is required — just OpenSSH, Nginx, and standard DNS tooling.

Source

vincent.bernat.ch — Read original →